Best of · Communication

Best mailbox access APIs for AI agents

All 9 ranked mailbox access APIs on the Anchor benchmark, with a pick for each need and where each one falls short. Scores come from public evidence, re-checked as vendors change.

  • 9 ranked
  • 3 agent-ready
  • 5 hosted endpoints
  • Updated 9 October 2026

Top three

Picks by need

Worked out from the scores, prices and facts, so they change when the research does.

Highest score overall

Nylas Email API A

A, 78.7/100 on the benchmark.

Also Gmail API, BB, 77.8/100.

Reliability

Gmail API BB

90/100 on reliability, against 77 for the overall leader.

Agent ergonomics

Gmail API BB

82/100 on agent ergonomics, against 81 for the overall leader.

Transparency & trust

Gmail API BB

82/100 on transparency & trust, against 81 for the overall leader.

Self-hosting under an open licence

EmailEngine BB

self-hosted, Source available under the EmailEngine licence agreement licence.

The shortlist

#ToolGradeBest forPriceWhere
1 Nylas Email API
Nylas
A 78.7 Products that act in their users' own mailboxes across several providers and want one schema, webhooks and OAuth handled. $15 / mo hosted
2 Gmail API
Google
BB 77.8 An agent working in a Gmail or Google Workspace user's own mailbox, with search, threads, drafts, labels and incremental sync at no per-account fee. Free hosted
3 EmailEngine
Postal Systems OÜ
BB 71.4 A team that must keep mailbox access on its own infrastructure, has many mailboxes across Gmail, Microsoft 365 and IMAP, and can run a server and Redis. $120.83 / mo local
4 Outlook Mail (Microsoft Graph)
Microsoft
B 66.3 Agents working in Microsoft 365 or Outlook.com mailboxes that need scoped reading, drafting, sending and incremental sync. Your plan hosted
5 Himalaya
Pimalaya
B 64.5 An agent with a shell that must work in one person's existing mailbox on any provider, including plain IMAP hosts, without a hosted intermediary. Free · OSS local
6 Unipile
UNIPILE SAS
C 58.4 A product that needs one API over Gmail, Outlook and IMAP together with LinkedIn or WhatsApp messaging, priced per account. $55 / mo hosted
7 Fastmail API (JMAP)
Fastmail Pty Ltd
C 54.1 An agent working in its owner's own Fastmail mailbox, where JMAP gives batched reads, structured search and state-based sync on an open standard, and MCP gives a ready connection with read, write and send levels. $6 / mo local
8 Zoho Mail API
Zoho
D 53.8 An agent working inside its owner's Zoho Mail mailbox or administering a Zoho Mail organisation, where narrow scopes and the MCP server keep access small. $1 / seat-mo local
9 Aurinko Email API
Yoxel, Inc.
E 44.2 A product that connects many users' Gmail and Microsoft mailboxes and wants one schema, delta sync, tracking and webhooks at a low price per account. Paid hosted

How to choose

  1. Scopes for read, draft and sendCheck whether reading, drafting and sending need separate scopes, since an agent that only drafts replies should not be able to send mail on the person's behalf.
  2. Search filters and thread readsCheck how search filters by sender, date and label, and whether a whole thread returns in one call, since one-by-one reads use up limits.
  3. Sync delay and new-mail eventsCheck how long new mail takes to appear and whether an event is pushed on arrival, since polling for new mail uses up limit calls.
  4. Send limits and sending addressCheck the send limit and the address mail is sent from, since a cap reached mid-task can leave a reply unsent.

How the benchmark tests this category. One test mailbox with the same two hundred messages on each provider. The same tasks run through each listing's API (search, read a thread, write a draft reply, send, label and archive, receive a new-mail event). We check scopes, sync delay and limits. In this run listings are graded from public evidence against the published checklist.

Each one in detail

#1

Nylas Email API

A 78.7/100

Unified email API from Nylas for reading, searching, drafting and sending mail in a person's existing Gmail, Microsoft 365, Exchange, Yahoo, iCloud or IMAP mailbox, with webhooks for new mail. A hosted MCP server exposes the same data.

Verdict One REST schema covers Gmail, Microsoft 365, Exchange, Yahoo, iCloud and IMAP, and IAM API keys launched on 6 October 2026 can be bound to a single mailbox with chosen permissions. The status page lists eight email incidents between 24 July and 17 September 2026, most on IMAP sync and webhooks.

Choose it for Products that act in their users' own mailboxes across several providers and want one schema, webhooks and OAuth handled.

Strengths

  • One schema for messages, threads, drafts, folders and attachments across Gmail, Microsoft 365, Exchange EWS, Yahoo, iCloud and IMAP
  • IAM API keys bound to one grant, workspace or application with chosen permissions, and 400 days of access activity
  • Idempotency-Key header on send, with documented 409 and 429 replay behaviour

Weaknesses

  • Eight status incidents on email between 24 July and 17 September 2026, including about six hours of IMAP retrieval and webhook degradation on 10 September
  • IAM principals and keys are managed only in the Dashboard, with no public API or CLI
  • On Google and Microsoft, search_query_native combines only with in, limit and page_token

Price $15 / moAuth OAuth or keyx402 nohosted

Full assessment

#2

Gmail API

BB 77.8/100

Google's REST API for Gmail mailboxes. It searches and reads messages and threads, writes drafts, sends mail, manages labels and settings, and reports mailbox changes through history records and Cloud Pub/Sub push notifications. Access is by OAuth 2.0.

Verdict Fourteen OAuth scopes separate labels, sending, metadata and read-only access, and the quota page gives every method a unit cost. Eight of the scopes are restricted, read-only and metadata among them, so a public app that reads mail needs Google's verification and an annual third-party security assessment. Gmail mailboxes only.

Choose it for An agent working in a Gmail or Google Workspace user's own mailbox, with search, threads, drafts, labels and incremental sync at no per-account fee.

Strengths

  • 14 OAuth scopes, with gmail.labels non-sensitive, gmail.send sensitive and permanent delete reserved for the full https://mail.google.com/ scope
  • Quota published per method, 5 units for messages.list, 20 for messages.get and 100 for messages.send, against 6,000 units a minute per user
  • history.list and Pub/Sub push notifications give incremental sync from a stored historyId

Weaknesses

  • Eight restricted scopes, including gmail.readonly and gmail.metadata, need restricted-scope verification for a public app
  • An app that stores or transmits restricted data on servers needs a security assessment by a Google-approved assessor every 12 months
  • No idempotency key on messages.send, and the error guide says a 200 response doesn't confirm the mail was sent

Price FreeAuth OAuthx402 nohosted

Full assessment · Against #1, Nylas Email API

#3

EmailEngine

BB 71.4/100

EmailEngine is self-hosted software from Postal Systems that puts one REST API over Gmail, Microsoft 365 and IMAP mailboxes, with webhooks for new mail and a beta MCP server. The owner runs it with Redis.

Verdict A self-hosted REST API over Gmail, Microsoft 365 and IMAP, with a public OpenAPI 3.0 spec and tokens that can be bound to one account, limited by action and group, and rate limited. It needs a server, Redis and a $1,450 yearly licence after a 14-day trial, and the MCP endpoint is a beta, off by default.

Choose it for A team that must keep mailbox access on its own infrastructure, has many mailboxes across Gmail, Microsoft 365 and IMAP, and can run a server and Redis.

Strengths

  • Public OpenAPI 3.0 spec for version 2.82.2 with 82 operations, plus llms.txt on both sites and a capabilities.json manifest
  • Tokens can be bound to one account, narrowed by action and group, limited by IP range, expiry and rate, and are stored only as SHA-256 hashes
  • Idempotency-Key header on both send routes, and 429 responses carry Retry-After and a ttl field

Weaknesses

  • Not open source. Running it beyond the 14-day trial needs a subscription at $1,450 or EUR 1,200 a year
  • The owner has to run a server and Redis. There is no hosted service, status page or SLA
  • The MCP endpoint is labelled beta, is off by default, and its tool set may change between releases

Price $120.83 / moAuth API keyx402 nolocal

Full assessment · Against #1, Nylas Email API

#4

Outlook Mail (Microsoft Graph)

B 66.3/100

Mail endpoints of Microsoft Graph for Outlook, Microsoft 365 and Exchange Online mailboxes. An app reads, searches, drafts, sends and files messages over REST with OAuth tokens from Microsoft Entra ID.

Verdict Delegated permissions split reading without bodies (Mail.ReadBasic), full reading, writing and sending, and delta queries and change notifications keep a local copy in step. sendMail takes no idempotency key and returns 202 before delivery, and each app is held to four concurrent requests per mailbox.

Choose it for Agents working in Microsoft 365 or Outlook.com mailboxes that need scoped reading, drafting, sending and incremental sync.

Strengths

  • Mail.ReadBasic reads messages without body, preview or attachments, and Mail.Send is separate from Mail.ReadWrite
  • Delta queries per folder and change notifications with missed and subscriptionRemoved lifecycle events
  • $select, $top (1 to 1,000, default 10), bodyPreview and Prefer: outlook.body-content-type="text" keep responses small

Weaknesses

  • sendMail has no idempotency key and answers 202 Accepted before delivery, so a retried send can go out twice
  • Four concurrent requests and 10,000 requests per 10 minutes for each app and mailbox pair
  • No prompt-injection guidance found in the mail reference or the Mail MCP reference, though message bodies come from outside senders

Price Your planAuth OAuthx402 nohosted

Full assessment · Against #1, Nylas Email API

#5

Himalaya

B 64.5/100

Himalaya is an open-source command-line email client from the Pimalaya project. It lists, searches, reads, composes and sends mail over IMAP, SMTP, JMAP, the Gmail API, Microsoft Graph and local stores, with JSON output for scripts and agents.

Verdict One binary reaches mailboxes on IMAP, JMAP, Gmail and Microsoft Graph with the same commands, and --json output has a JSON Schema for each command. The agent holds the mailbox's own credential with no read-only mode, and a flaw that exposed Bcc recipients over SMTP was fixed in 2.2.1 on 2 October 2026.

Choose it for An agent with a shell that must work in one person's existing mailbox on any provider, including plain IMAP hosts, without a hosted intermediary.

Strengths

  • Shared commands for mailboxes, envelopes, flags, messages and attachments run the same way over IMAP, JMAP, Gmail, Microsoft Graph, Maildir and mbox
  • himalaya json-schema prints a JSON Schema for the --json output of 90 commands, and message read --json returns one designed view on every backend
  • Secrets come from a shell command such as pass show, so a password or token need not sit in the config file

Weaknesses

  • Until 2.2.1 of 2 October 2026, message send transmitted the Bcc: header to every recipient over SMTP (issue #747, reported 12 September 2026)
  • No read-only mode, no confirmation before a send or delete, and no idempotency key on send were found
  • SECURITY.md sends vulnerability reports to the public issue tracker. No security.txt, private reporting route or published advisory was found

Price Free · OSSAuth OAuth or keyx402 nolocal

Full assessment · Against #1, Nylas Email API

#6

Unipile

C 58.4/100

Unipile is a hosted API from Unipile SAS in France that connects to accounts people already have. It reads, searches, sends and files mail in Gmail, Outlook and IMAP mailboxes, and also covers calendars, LinkedIn, WhatsApp, Instagram and Telegram.

Verdict One REST API covers Gmail, Outlook and IMAP with search, drafts, send with an idempotency key and new-mail webhooks, and the OpenAPI spec is public. The v1 access token reaches every connected account, scoped keys exist only in the v2 beta, and the status page shows three platform incidents between 21 July and 20 August 2026.

Choose it for A product that needs one API over Gmail, Outlook and IMAP together with LinkedIn or WhatsApp messaging, priced per account.

Strengths

  • Public OpenAPI 3.0 spec with 94 operations, readable without a key, plus llms.txt and a Markdown copy of every docs page
  • POST /api/v1/emails accepts an Idempotency-Key header of up to 255 characters, so a retried send returns the first result
  • GET /api/v1/emails has cursor pagination, limit up to 250, meta_only, a full-text search and filters for folder, sender, recipient and date

Weaknesses

  • A v1 access token reaches every connected account. Scoped keys, documented rate limits and retry-after exist only in the v2 beta
  • status.unipile.com shows platform incidents on 21 July, 30 July and 20 August 2026, the last an API node unavailable for 70 minutes
  • The v1 Node SDK on npm is 1.9.3 from 21 May 2025. The newer Node and Python SDKs work only with the v2 beta

Price $55 / moAuth API keyx402 nohosted

Full assessment · Against #1, Nylas Email API

#7

Fastmail API (JMAP)

C 54.1/100

Fastmail is a paid email, calendar and contacts host from Fastmail Pty Ltd in Melbourne. Agents reach a customer's mailbox through JMAP at api.fastmail.com, the open IETF protocol, or through the company's own MCP server.

Verdict A mailbox API built on the open JMAP standard, with read-only tokens, six OAuth scopes and an MCP server that separates read, write and send access. Fastmail publishes no OpenAPI file, SDK, API changelog, request rate limit or SLA, and its customer terms forbid programmatically generated email to addresses outside the account.

Choose it for An agent working in its owner's own Fastmail mailbox, where JMAP gives batched reads, structured search and state-based sync on an open standard, and MCP gives a ready connection with read, write and send levels.

Strengths

  • JMAP is an IETF standard (RFC 8620, 8621 and 9610), so requests, types and errors are specified in public and not tied to one vendor
  • API tokens can be read-only or limited to mail, sending, contacts or Masked Email, and are revocable in settings
  • OAuth 2.0 requires PKCE with S256, rotates refresh tokens on every use and revokes the grant if an old one is replayed

Weaknesses

  • The customer terms forbid programmatically generated email to addresses outside the account, and say the service is not for machine-to-machine workflows
  • No OpenAPI file, llms.txt, official SDK or API changelog. The developer page points to the RFCs and four sample scripts
  • No request rate limit, Retry-After guidance or SLA was found, and the API terms allow backwards-incompatible changes with notice only promised as an attempt

Price $6 / moAuth OAuth or keyx402 nolocal

Full assessment · Against #1, Nylas Email API

#8

Zoho Mail API

D 53.8/100

Zoho Mail is Zoho's hosted business email service. Its REST API lets an application read, search, send and organise mail in a Zoho Mail account and administer an organisation's users, domains, groups and policies, with OAuth 2.0 access.

Verdict A REST API over a Zoho Mail mailbox with OAuth scopes that narrow to one resource and one operation, plus an MCP server launched in 2026. Zoho publishes no OpenAPI file, SDK, request rate limit or API changelog, and its usage policy bars automated email.

Choose it for An agent working inside its owner's Zoho Mail mailbox or administering a Zoho Mail organisation, where narrow scopes and the MCP server keep access small.

Strengths

  • OAuth scopes name one resource and one operation, such as ZohoMail.messages.READ, so an agent can hold read access without send or delete.
  • Every reference page has a Markdown twin, indexed in https://www.zoho.com/mail/help/llms.txt, with a curl sample and a sample response.
  • Zoho Mail MCP exposes the API methods as tools on a remote server, and the owner picks which tools a server carries.

Weaknesses

  • The Zoho Mail usage policy, updated 2 September 2026, lists automated, bulk and transactional emails among uses that are not allowed.
  • No OpenAPI file, official REST SDK or dated API changelog was found. The path carries no version.
  • The getting started guide says each API has its own rate limit and gives no numbers. The response code list has no 429.

Price $1 / seat-moAuth OAuthx402 nolocal

Full assessment · Against #1, Nylas Email API

#9

Aurinko Email API

E 44.2/100

Unified email REST API from Yoxel, Inc. It reads, searches, drafts and sends mail in a user's own mailbox on Gmail, Office 365, Outlook.com, Exchange, Zoho Mail, iCloud and IMAP, with delta sync, open and reply tracking and webhooks.

Verdict One REST interface covers message search with 17 query operators, drafts, sending, folders and delta sync across seven mailbox types, at $1.50 an active account a month and with send-only and read-only scopes. No status page, SLA, changelog, idempotency key on send or official SDK was found, and SOC 2 is not yet held.

Choose it for A product that connects many users' Gmail and Microsoft mailboxes and wants one schema, delta sync, tracking and webhooks at a low price per account.

Strengths

  • Public OpenAPI 3.0 description at apirefs.aurinko.io/assets/swagger.json, with 43 email operations, 34 of them carrying a cURL sample
  • Four mail scopes. Mail.Read allows no writes, Mail.Send allows sending with no read access, and Mail.ReadWrite excludes send
  • The q parameter takes 17 search operators, with a table in the docs saying where IMAP and Exchange support is partial

Weaknesses

  • No status page, incident history or SLA found, and the terms supply the service as is
  • No idempotency key on POST /v1/email/messages, so a retried send can deliver twice
  • No changelog, deprecation policy or official SDK found in the docs or on the site

Price PaidAuth OAuthx402 nohosted

Full assessment · Against #1, Nylas Email API

Head to head

All 36 comparisons in this category

Questions

What are the highest-rated mailbox access APIs for AI agents?

Nylas Email API has the highest benchmark score of the 9 ranked mailbox access APIs, 78.7 (A). Gmail API is second with 77.8 (BB).

How many mailbox access APIs are agent-ready?

3 of the 9 ranked here grade BB or better, the bar for agent-ready on the Anchor benchmark.

Which mailbox access APIs accept x402 payments?

None of the ranked listings here accepts x402 for its main call yet.

How is this list ranked?

By the Anchor benchmark score out of 100, a weighted mean of the scored categories minus deductions for negative events, from public evidence re-checked as vendors change. Listings cannot pay for a place. The latest assessment behind this page is from 9 October 2026.

How this list is made

The order is the Anchor benchmark score, the same number as on each listing and in the top list. Each listing is graded from public evidence against the benchmark checklist, and the picks above are worked out from those grades, prices and facts. No listing pays for its place, and paid audits or listing help never change a score.

Full ranked table · 36 head-to-head comparisons · Best tools in every category

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.